Apache disclosed CVE-2026-56452, a moderate-severity path traversal flaw in the sshd-scp component of Apache MINA SSHD that lets a malicious SCP sender write files to attacker-controlled locations during file reception. The issue stems from improper validation of filenames supplied in SCP C or D commands, creating a risk for applications that use Apache MINA SSHD to receive files over SCP.
The vulnerability affects org.apache.sshd:sshd-scp through 2.18.0 and 3.0.0-M1 through 3.0.0-M4. Apache said applications using Apache MINA SSHD 2.0.0 or later are impacted only if they rely on sshd-scp for inbound file transfers, and it released fixes in 2.19.0 and 3.0.0-M5. The flaw was reported by Unbbal.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
An oss-security disclosure described CVE-2026-56452 as a moderate-severity path traversal flaw in Apache MINA SSHD's sshd-scp component. The vulnerability stems from missing filename validation in SCP "C" and "D" commands during file reception.
Apache fixed a path traversal vulnerability in the sshd-scp component that allowed a malicious SCP sender to write files to attacker-controlled locations during file reception. The issue affects org.apache.sshd:sshd-scp through 2.18.0 and 3.0.0-M1 through 3.0.0-M4, and the finder is credited as Unbbal.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.